Custom organizational workshops
Your research should reveal the subject.
Not your team.
Privacy training for research teams whose online work can expose their interests, identities, and relationships. Build habits your people can use when the work gets sensitive.
Built around the work
Different missions. Real privacy decisions.
Start with a task your people actually do. Adapt the examples, technical depth, and operating practices to the people—and relationships—you need to protect.
01 / Research teams
Investigate a subject without advertising your organization’s interest.
Repeated visits, signed-in accounts, shared browser setups, and document metadata can reveal the direction of a project before your team is ready to share it.
For researchers, analysts, intelligence teams, and their security leads.
Explore this use caseIn the workshop
Map an investigation from search to document sharing. Identify which steps reveal an organization, an individual, or a connection between projects.
Work toward
A research workflow with defined account boundaries, approved tools, and clear rules for handling material.
02 / Journalists
Protect the relationship between a reporter, a story, and a source.
A secure message is only one part of the workflow. Browser activity, contact discovery, shared files, and personal accounts can expose the surrounding relationship.
For newsrooms, investigative reporters, editors, and freelance collectives.
Explore this use caseIn the workshop
Walk through a fictional source interaction: first contact, research, receiving files, collaboration, and publication. Discuss safer handoffs at each stage.
Work toward
A source-handling checklist and a compartmentalized research setup that staff can explain and repeat.
03 / Law firms
Keep confidential work from leaking into everyday digital habits.
Client research can cross personal accounts, browser extensions, cloud documents, and third-party services. Those choices deserve the same care as the information inside a case file.
For attorneys, legal researchers, administrators, and firm security teams.
Explore this use caseIn the workshop
Review a fictional client intake and research workflow. Practice account separation, sharing permissions, document hygiene, and vendor evaluation.
Work toward
A practical handling guide for staff, with escalation points and policy questions for the firm’s legal and IT owners.
04 / Human rights
Reduce the exposure a routine task creates for the people you support.
Public advocacy, sensitive casework, field coordination, and partner communications can require different identities and different levels of visibility.
For human rights organizations, advocates, nonprofits, and field coordinators.
Explore this use caseIn the workshop
Use a fictional advocacy scenario to map affected people, observers, and consequences. Choose communication and device practices appropriate to that context.
Work toward
A role-based privacy plan that accounts for partners, volunteers, staff turnover, and realistic device constraints.
05 / CISOs & security teams
Turn privacy policy into behavior your teams can actually sustain.
Access controls and endpoint protection matter. They do not, on their own, decide what a legitimate website, vendor, or signed-in service learns from a staff member’s work.
For cisos, security leaders, it administrators, privacy officers, and team managers.
Explore this use caseIn the workshop
Select a high-exposure workflow, map existing controls, and identify privacy gaps. Design a usable baseline with exceptions, ownership, and a review cadence.
Work toward
A training plan, a prioritized configuration backlog, and an operating guide your security and privacy owners can maintain.
For security & privacy leaders
Secure systems.
More deliberate exposure.
Your team can use patched devices, encrypted connections, and MFA while still disclosing sensitive interests through normal, authorized activity. Privacy training helps people examine what their work reveals and make better decisions within your existing controls.
NIST distinguishes privacy risks arising from data processing from risks caused by cybersecurity incidents. See the relationship in NIST’s Privacy Framework.
Cybersecurity asks
Who can access the system?
Authentication, patching, endpoint protection, and incident response help protect systems and information.
Privacy also asks
What does using it reveal?
Account links, browsing signals, sharing choices, retention, and vendor visibility shape the exposure of legitimate work.
One operating plan, coordinated with your IT, security, and privacy owners.
For participants
Recognize exposure, choose a suitable workflow, practice configurations, and know when to ask for help.
For your organization
Work toward a shared baseline, usable checklists, named owners, and fewer ad hoc tool decisions.
For the CISO
Connect staff behavior to operational risk. Define adoption checks, exceptions, and priorities for technical follow-up.
Build your curriculum
Practical skills, from the device to the policy.
Choose the modules that address your exposure. These are scoping options for a custom engagement; a single session focuses on an agreed subset, with time to practice.
Threat modeling & everyday OPSEC
Define what you need to protect, who can observe it, and what a disclosure would mean. Practice preparation, travel and remote-work routines, safe handoffs, and escalation when a workflow goes wrong.
Build an observer map for one routine task.
Browser privacy & attribution
Understand cookies, fingerprinting, extensions, private windows, and the difference between changing an IP address and changing what a website can recognize. Choose browsing boundaries around the work.
Compare a personal, organizational, and research workflow.
Device setup & configuration
Review browser settings, app permissions, updates, disk encryption, screen locks, backups, location sharing, and browser sync. Build an approved baseline around your operating systems and device-management requirements.
Walk through a configuration checklist on a practice device.
Privacy tools & VPN hygiene
Evaluate browsers, password managers, messaging tools, VPNs, and 404 by purpose, trust model, maintenance, compatibility, and limits. Cover connection checks, DNS and routing, disconnect behavior, and when a VPN does not solve the problem.
Choose controls for a scenario and explain what remains visible.
Accounts, identities & recovery
Separate work, personal, and sensitive-project accounts. Review password management, MFA, recovery paths, shared accounts, cloud sync, onboarding, and offboarding. Discuss when separate browser profiles are useful and where their boundaries end.
Sketch an account map and a recovery plan without sharing credentials.
Communication & information handling
Practice safer file sharing, metadata review, recipient verification, communication-channel selection, retention, and access decisions. Consider the people exposed by the workflow as well as the person operating it.
Rehearse a fictional sensitive handoff.
Policies & a privacy-centered ethos
Translate principles into practical rules for collection, consent, approved tools, retention, and escalation. Review employee privacy as well as commitments to clients, sources, research participants, and partners.
Draft a commitment and assign an owner, a practice, and a review date.
Technical & leadership briefings
Give engineers a deeper view of attribution surfaces and mitigation tradeoffs, or help leadership understand operational exposure, procurement decisions, and priorities. Adjust depth to the people making the decisions.
Explain one privacy risk in operational terms and propose the next action.
Inside a session
See it. Practice it. Explain it back.
A workshop moves from a recognizable situation to a decision participants can repeat. Demonstrations explain the mechanism; guided exercises turn that understanding into a habit.
- 01
Map the task
Start with a fictional workflow drawn from your team’s work. Agree on the information and relationships that matter.
- 02
See the exposure
Use demonstrations and an observer map to show what accounts, devices, browsers, and services can reveal.
- 03
Practice a change
Work through an approved configuration or a safer handoff. Explain the tradeoffs and check understanding.
- 04
Make it repeatable
Document a checklist, assign ownership, and identify follow-up work. Participants explain the workflow back in their own words.
Example exercise
“We turned on a VPN.
Can the site still know it’s us?”
Using a fictional research task, participants map the network route, account login, browser storage, and browser signals. They decide what the VPN changes, what remains connected, and which additional boundary the task needs.
The takeaway is a reasoned workflow decision, with its limits written down—not a score claiming that a person is anonymous.
Explore the browser fingerprinting guide →Agree on the takeaways before we begin
A tailored checklist, configuration baseline, workflow map, recommended reading, policy draft, or follow-up action list can be included in scope. The materials and any adoption review are specified in your proposal.
Privacy as an organizational practice
A mission statement people can put into practice.
A privacy-centered ethos belongs in how your organization treats its employees, clients, sources, participants, and partners. We can help your team draft a mission statement and translate it into decisions about tools, collection, access, retention, and communication.
Policy work connects each commitment to an owner and an achievable practice. Your legal and policy owners review formal statements before adoption or publication.
Delivery & customization
Fit the session to your people.
Choose a facilitated remote session, or discuss an on-site workshop by arrangement. Delivery, location, accessibility needs, group size, and device constraints are agreed during scoping.
Team briefing
A focused introduction for staff or leadership. Shared language, relevant demonstrations, and decisions to take back to your team.
Best for: establishing a common starting point.
Hands-on workshop
Guided exercises in a demonstration environment or an agreed device setup. Participants practice the workflow and build a usable checklist.
Best for: changing a specific day-to-day practice.
Custom training series
Separate sessions for different roles, with room to revisit configuration, policy, and adoption. Preparation and follow-up are agreed in scope.
Best for: embedding practices across an organization.
Before the session
We discuss your audience, priority workflow, existing controls, and desired outcomes. We agree on prerequisites, practice environments, materials, and whether device changes are appropriate.
During and after
Participants can use fictional examples and demonstration accounts. Any real-device configuration follows your organization’s approvals; recordings and follow-up support are discussed in advance.
Seth teaches computer science and literature and develops 404’s privacy tools. That combination shapes these workshops: technical mechanisms explained clearly, questions welcomed, and time to test understanding through practice.
The engineering work brings browser and network behavior into the lesson. The teaching experience helps make those details useful to people with different backgrounds—from a nontechnical staff member to the engineer maintaining the configuration.
When you need evidence first
Let your environment
inform the training.
An Attribution Risk Audit can assess recognizability across an agreed set of browsers, devices, networks, and workflows. Its findings can help prioritize which practices deserve training and which require engineering work.
An audit is a separate, optional engagement. You can book a workshop without commissioning one, or scope both around a shared operational question.
Explore the Attribution Risk Audit ↗Before you book
A few practical questions.
Are workshops available, or are all your courses still in development?
Custom organizational workshops can be scoped now. The separate self-paced course catalog is still in development; no published course enrollment is being offered here.
Does our team need technical experience?
No. We can scope a staff workshop around everyday tasks, a technical session for administrators and engineers, or a leadership briefing. The examples and depth are agreed before the session.
Can you recommend and help configure specific tools?
Yes, within the agreed scope. Recommendations start with your workflow, supported devices, existing controls, and maintenance capacity. Any installation or managed-device change is coordinated with your IT owner; a workshop does not grant access to your systems.
Will participants need to expose sensitive work or personal accounts?
We can use fictional scenarios and demonstration accounts. Sensitive client or source material, credentials, and personal account access are not needed for a training exercise. Any review of real organizational material is separately agreed during scoping.
How long is a workshop, and what does it cost?
Duration, group size, delivery, preparation, materials, and any follow-up are scoped to your needs. Send a short inquiry to discuss an appropriate format; we agree on scope, a quote, and timing before confirming a session.
Will this make us anonymous or certify compliance?
Training helps people make informed, repeatable decisions and reduce avoidable exposure. It does not guarantee anonymity or provide a compliance certification. Your legal and policy owners review any formal commitments.
Further reading & technical foundations
Start with one workflow
What should your team
feel prepared to do?
Tell us your organization type, approximate participant count, priority task, preferred delivery, and timing. A short description is enough—please leave out credentials and confidential client or source information.
- 01 Send an inquiry
- 02 Agree on scope & quote
- 03 Confirm your session
Workshops for your team
Privacy training for organizations
Help your team understand browser fingerprinting, digital tracking, and practical privacy controls. Tell us what your organization needs.
Please keep credentials, confidential client information, source material, and regulated data out of this public form.
Delivered by email. No mailing-list signup. Cloudflare provides spam verification. Privacy policy.